Security Policy

Yaraku Translate Security
Yaraku Translate has established a robust information management framework and operates the service with the utmost care so that you can use it confidently in your business.
Security Features

- Customer-Specific Data Management
- Data Encryption
- Continuous Data Backups
- 24/7 System Monitoring
- Vulnerability and Hacking Countermeasures
- SSO (Single Sign-On)
- Private Cloud Deployment
Compliance Programs
Yaraku Translate has obtained the certifications listed below.

ISMS (ISO/IEC 27001:2022) Certification
Yaraku, Inc.’s Tokyo HQ obtained certification under the international information security management system (ISMS) standards ISO/IEC 27001:2022 and JIS Q 27001:2023 on December 22, 2022.
Summary of Certification and Registration
Registered Organization: Yaraku Inc.
Scope of certification registration: Planning and development of multilingual communication tools and provision of related services
Certification Standard: ISO/IEC 27001:2022, JIS Q 27001:2023
Certificate Number: IS778669
Certification Registration Date: December 22, 2022
Last Updated Date: November 29, 2025

Data Management in Yaraku Translate
Data stored in Yaraku Translate is managed so that your privacy remains protected.

Database
In Yaraku Translate, each customer’s translation data is managed separately. This prevents third parties from accessing or modifying the database. At Yaraku, Inc., only authorized employees may access the database, and only for system maintenance or troubleshooting.
We do not disclose data except in specific circumstances, such as with the customer’s consent or when required by law.
Data in the database is continuously backed up. If data is lost due to human error, it can be restored using backups retained for the previous 14 days.

Encryption
In Yaraku Translate, all communications are encrypted using SSL (*). This prevents third parties from viewing or tampering with the content. Highly confidential data, such as passwords, is also encrypted in the database.
*SSL stands for Secure Sockets Layer, a mechanism widely used on websites, including online payment pages, to encrypt communications and prevent eavesdropping and tampering.
Vulnerability and Hacking Countermeasures
To protect our customers’ valuable data, we implement a range of vulnerability and hacking countermeasures.

Vulnerability Countermeasures
We conduct regular vulnerability testing to verify system security. We also monitor the system 24/7, continuously tracking disk usage, memory, CPU utilization, and other operating conditions so that abnormalities can be detected.

Hacking Countermeasures
Our systems are protected by firewalls against unauthorized access and other security threats.
Yaraku Translate implements measures to mitigate hacking risks to its servers and databases, including SQL injection, cross-site scripting, OS command injection, HTTP header injection, and improper session management.
Yaraku Translate Infrastructure
Yaraku Translate runs on AWS infrastructure that meets stringent security requirements.

Data Centers
Yaraku Translate uses Amazon Web Services (AWS) data centers. AWS servers are distributed across multiple data centers, each with independent power, cooling, and network infrastructure. If one data center experiences an outage, the service automatically switches to servers operating in another data center to maintain continuity.
AWS data centers implement physical security, disaster preparedness, and risk management measures. For more information about AWS security, see the AWS Security Center and the AWS Data Center Controls pages.
Options for Flexible Security Policies
A range of options is available to help you adopt Yaraku Translate with confidence.

Security Options
- SSO: Supports SAML (Security Assertion Markup Language)-based single sign-on and integration with identity providers such as Microsoft ADFS and Google Workspace.
- IP Address Restrictions: Restricts access to Yaraku Translate to specified IP addresses.
- Password Policy Settings: Set requirements for periodic password changes, the use of uppercase and lowercase letters and numbers, minimum password length, and more.
- Automatic Document Deletion: Deletes confidential translation documents automatically after a specified period.
- Server Options: Deploy Yaraku Translate in a virtual private cloud (VPC) based on your security requirements. For details, please contact us through the Inquiry page.

Integration Partner
Sony Network Communications Inc. leverages the technical expertise and know-how it has developed as an internet service provider to support robust and secure implementation of Yaraku Translate.
In addition to integration services such as security measures and server configuration, support is also available for maintenance and operations tailored to each customer’s requirements.
Information Security Policy
Basic Philosophy
Yaraku, Inc. (hereinafter referred to as “the company”) conducts business based on the philosophy of “enjoying global communication”.
The Information assets handled by the company, such as customer information, are extremely important to us as the foundation of our business.
To guard against the risk of leakage, damage, loss, etc., we recognize the importance of protecting information assests and all personnel who handle information assests, including officers of the company and any personnel responsible for information protection, must comply with the following policy to maintain the confidentiality, integrity, availability, and other aspects of information security of information assets.
Basic Policy
- In order to protect information assets, we will formulate an information security policy and related regulations; and conduct business in accordance with this policy, as well as comply with legislaion, regulations, and other norms related to information security, as well as contractually-agreed terms with customers.
- We will determine the criteria for analyzing and evaluating risks such as leakage, damage, and loss of information assets, establish systematic risk assessment methods, and carry out risk assessments on a regular basis. Based on the results, we will implement necessary and appropriate security measures.
- We will establish an information security system centered on the officer in charge and clarify authority and responsibility for information security. In addition, all employees will be made aware of the importance of information security with regular education, training and development provided to ensure the proper handling of information assets.
- We will regularly inspect and audit the status of compliance with the information security policy and the handling of information assets, and promptly take corrective action for any deficiencies that are discovered or make improvements based on the inspection.
- In addition to taking appropriate measures against the occurrence of information security events and incidents, we will establish response procedures and protocols in advance such that in the unlikely event that an incident occurs, the damage will be minimized and all appropriate parties are notified as we respond and take appropriate corrective action. In addition, particularly for incidents related to business or service interruption, we will ensure business continuity by establishing a management framework and periodically reviewing it.
- We will establish and implement an information security management system with goals to realize our basic philosophy, while continuously reviewing and improving it.
Established September 30, 2022
Yaraku Inc.
Chief Executive Officer: Sakanishi Suguru